All the latest UK technology news, reviews and analysis

Exploit code targets WordPress bloggers

by Shaun Nichols

06 Mar 2007

Be the first to comment

  • Tweet this
Blogs
Hackers broke into the WordPress download server early last week

Attackers have injected exploit code into the downloadable software for the WordPress blogging service. 

The open source software allows users to set up and publish postings to a blog. The company has issued an update that repairs the vulnerability.

Although blogging services such as Blogger, TypePad and WordPress allow users to publish blog postings directly from a browser, client software offers users more flexibility.

Hackers broke into the WordPress download server early last week and embedded attack code into the 2.1.1 update of the application.

The malware opened a backdoor on infected systems that could allow an attacker to execute code and install software.

WordPress founding developer Matthew Mullenweg said on a company blog that the infected software was offered to users for three to four days as an official download before the company was alerted to the breach. 

"This is the kind of thing you pray never happens," said Mullenweg. "But it did and we are dealing with it as best we can."

Security vendor Symantec said that it had uncovered fewer than 50 attacks exploiting the backdoor. The firm rated the threat as 'low-level' because of its limited reach and easy removal. 

WordPress is recommending all users to upgrade to version 2.1.2 of the software, and has urged administrators hosting WordPress blogs to prevent access to the 'theme.php' and 'feed.php' files that are infected by the attack.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

25%

1%

11%

63%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Helpdesk/Service Analyst x3

Helpdesk/Service Analyst x 3 3 Month Contract...

2nd/3rd line Technical support EMEA (FRENCH SPEAKING)

French Technical support Specialist (2/3rd Line) CCNA...

ECM Project Manager - CMS, Document Management, Web 2.0

ECM Project Manager - CMS, "Document Management", Web...

PRESALES CONSULTANT/TECHNICAL CONSULTANT (CCNA, MCITP)

Skills - Presales, Consultant / Consultancy, Technical...

To send to more than one email address, simply separate each address with a comma.